SiteEgress compliance

Compliance mapping.

This page maps product behavior to common review questions. Legal applicability depends on the publisher, user, deployment, jurisdiction, and use case.

This page explains product practices and is not a certification or legal opinion.

TopicProduct practiceEvidence and boundary
Single purposeWebsite privacy and browser-visible data-flow inspectionProduct pages, manifest description, and extension UI use the same narrow purpose.
Query-string minimizationSanitized parameter names onlyParameter values are not inspected or retained; the result remains browser-visible technical evidence.
Data minimizationRetain metadata and categories instead of typed valuesNo passwords, form values, Cookie values, storage values, bodies, or raw destination IPs in reports.
User choiceOptional history and Geo InsightsBoth features are off by default and can be cleared or disabled.
User-controlled comparisonManual before/after Privacy Checkpoints and local receipt exportThe extension never clicks consent controls and never presents the result as legal proof.
TransparencyExplainable evidence types, score limits, permissions, and third-party lookupPrivacy policy names ipwho.is and explains country-location limitations.
Limited useAudit data is used only for the product's user-facing purposeNo sale, advertising profile, creditworthiness use, or unrelated transfer.
SecurityPackaged code, bounded data, sanitization, and restrictive exportsSecurity page and responsible disclosure channel document the controls and limitations.
Optional local bridgeDual opt-in and minimized evidence exchange with Agent GuardNo new Chrome permission; no value-bearing content or raw IP addresses; peer context cannot rewrite the audit.
Reference frameworks

How the product relates to common review questions

Chrome Web Store

The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.

GDPR concepts

The design supports data minimization, purpose limitation, transparency, user choice, and local deletion. This is not a determination that a user or publisher is compliant.

CCPA/CPRA concepts

SiteEgress does not sell or share audit data for cross-context behavioral advertising. Applicability and controller/business duties remain case-specific.

Enterprise review

Organizations should separately assess browser policy, approved extensions, third-party lookup rules, retention, legal basis, and incident-response requirements.